{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-35511/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["authorizer"],"_cs_severities":["high"],"_cs_tags":["account-takeover","oauth","authentication-bypass","cve-2026-35511"],"_cs_type":"advisory","_cs_vendors":["Authorizer"],"content_html":"\u003cp\u003eAuthorizer, an open-source authentication platform, contains a critical identity linking vulnerability (CVE-2026-35511) that allows for zero-click account takeover. The flaw exists in the OAuth callback handler, which incorrectly merges identity provider data into existing unverified accounts without validating the ownership of the associated email address. An attacker can pre-register an account using a target's email address and a custom password without verifying the email. When the victim subsequently performs a legitimate OAuth login, the application links the OAuth identity to the attacker's pre-staged account, marks the email as verified, and retains the attacker's password. This grants the attacker persistent, unauthorized access to the victim's account, including all data added after the OAuth login. This vulnerability affects all Authorizer deployments using versions prior to 0.0.0-20260807033110-66fe488fd2a4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker registers a new account on an Authorizer instance using the target's email address (\u003ccode\u003evictim@company.com\u003c/code\u003e) and a password known only to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker intentionally ignores the email verification prompt, leaving the account in the database with \u003ccode\u003eEmailVerifiedAt = nil\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe victim, unaware of the pre-staged account, logs in to the platform using a legitimate third-party OAuth provider (e.g., Google or GitHub).\u003c/li\u003e\n\u003cli\u003eThe OAuth callback handler processes the request and identifies that an account with \u003ccode\u003evictim@company.com\u003c/code\u003e already exists in the local database.\u003c/li\u003e\n\u003cli\u003eThe application merges the OAuth identity into the attacker's account, updating the \u003ccode\u003eSignupMethods\u003c/code\u003e field to include the provider.\u003c/li\u003e\n\u003cli\u003eThe application logic automatically verifies the account's email address (\u003ccode\u003eEmailVerifiedAt\u003c/code\u003e is set to the current timestamp), trusting the OAuth identity without validating ownership.\u003c/li\u003e\n\u003cli\u003eThe application saves the merged user state to the database, leaving the attacker's initial password intact and valid.\u003c/li\u003e\n\u003cli\u003eThe attacker authenticates to the account using the email and their original password, successfully performing an account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to achieve full account takeover. The attacker maintains persistent password-based access to the victim's account regardless of whether the victim later revokes the OAuth linkage. This leads to unauthorized data access and the potential for long-term credential abuse across all configured OAuth providers supported by Authorizer, including Google, GitHub, Facebook, and Microsoft.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and platform engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all Authorizer instances to version 0.0.0-20260807033110-66fe488fd2a4 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview database logs for accounts where \u003ccode\u003eEmailVerifiedAt\u003c/code\u003e was updated automatically via an OAuth callback flow to identify potentially compromised accounts.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable OAuth identity linking and require re-authentication via the primary password method to ensure account ownership.\u003c/li\u003e\n\u003cli\u003eAudit all user accounts for inconsistencies in \u003ccode\u003eSignupMethods\u003c/code\u003e or unexpected verification timestamps that coincide with OAuth login events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T20:07:12Z","date_published":"2026-08-14T20:07:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-authorizer-oauth-takeover/","summary":"Authorizer suffers from a zero-click account takeover vulnerability (CVE-2026-35511) where attackers can link OAuth identities to unverified accounts, gaining persistent password access to victim accounts.","title":"Authorizer Zero-Click Account Takeover via OAuth Identity Linking","url":"https://feed.craftedsignal.io/briefs/2026-08-authorizer-oauth-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-35511","version":"https://jsonfeed.org/version/1.1"}